PoC Index

CVE-2024-3901

MEDIUM 6.8EPSS 0.6%

The Genesis Blocks WordPress plugin through 3.1.3 does not properly escape attributes provided to some of its custom blocks, making it possible for users allowed to write posts (like those with the contributor role) to conduct Stored XSS attacks.

CVSS v3.1
6.8 MEDIUMCVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:H/I:H/A:H
EPSS
0.55% chance of exploitation in the next 30 days, 44th percentile
Published
2025-05-15
Updated
2025-11-13

Proof-of-concept exploits (1)

References

Related